Map the
attack surface.
Assessed internet-facing assets using EasyDMARC, openSquat, Gobuster, and Shodan. Examined exposed services, DNS configurations, subdomains, and domain-squatting risks.
I’m Samuel Graziano. I bring hands-on experience in external reconnaissance, threat hunting, and purple team testing—and a curiosity for what comes next.
Assessed internet-facing assets using EasyDMARC, openSquat, Gobuster, and Shodan. Examined exposed services, DNS configurations, subdomains, and domain-squatting risks.
Developed five hypothesis-driven threat hunts around post-compromise identity activity. Created reusable Sigma and KQL queries and presented findings and detection recommendations.
Supported authorized, MITRE ATT&CK-aligned testing across discovery, RDP activity, policy manipulation, tool transfer, and credential access to evaluate security visibility.
Hands-on security work spanning external reconnaissance, controlled adversary testing, and identity-focused threat hunting.
Splunk / Microsoft Defender / Wireshark / Suricata / Snort / YARA / Volatility / Autopsy / FTK / FTK Imager
Shodan / EasyDMARC / openSquat / Gobuster / DNS & DNSSEC analysis
Python / KQL / PowerShell / Linux CLI / Sigma
Linux (Ubuntu, Debian, Kali) / Windows Client & Server / macOS / Cisco IOS / pfSense / Switch security / Azure / AWS
A space for hands-on security projects, technical write-ups, and lessons learned. As I build, I’ll share the process and the findings here.
Future work across red, blue, and purple team disciplines.Exploring red, blue, and purple team opportunities.
Reach out to discuss where I can contribute.